Impact
The flaw resides in MongoDB Server's LDAP authorization integration. Pooled LDAP connections may hold a stale authenticated identity after a successful user login when certain configurations are active. When subsequent authorization requests are processed, the server may use the wrong LDAP identity, leading to role assignments that do not match the intended access control rules. This unintended privilege escalation is a form of authorization bypass, classified as CWE‑863.
Affected Systems
MongoDB Server is affected. No specific version ranges are listed; all deployments that use the LDAP authorization feature and employ pooled connections are potentially vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.6, indicating moderate to high risk. The EPSS score is unavailable, but the issue is not in CISA’s KEV catalog, suggesting limited public exploitation data. The attack vector is inferred to involve an authenticated user able to trigger LDAP authentication under a configuration that enables connection pooling; the attacker could thus obtain elevated privileges over the deployment’s authorization policy.
OpenCVE Enrichment